Our Policies
Last Updated: September 13, 2026
These policies describe how Aparagon collects, protects, and retains Client Data on behalf of Advertisers and Agencies using the Aparagon Marketing Platform. They supplement, and do not replace, our Terms of Service.
APARAGON CLIENT DATA PROTECTION POLICY
Version 1.2
Introduction
To help power the Aparagon Insights Engine for the purposes of the Services, as defined in the Terms, an Advertiser must provide relevant first-party data that it has collected from its customers, known as Advertiser-Provided Customer Data (“Client Data”). Client Data travels through one of three pathways: Advanced Integration, Aparagon Conversion Events (“ACE”), and Simple Integration.
Under Advanced Integration and ACE, Aparagon receives, processes, and hashes Client Data directly, following the same protection pipeline described below. Under Simple Integration, by contrast, the Amazon Ad tag captures event data directly into systems controlled by Amazon, and Aparagon receives only aggregated, privacy-safe outputs, not the underlying data itself.
Purpose
This document describes the protections Aparagon applies to Client Data it receives and processes directly, under Advanced Integration and ACE, and clarifies Aparagon’s more limited role with respect to Simple Integration, where the underlying event data never reaches Aparagon.
Scope
The protections described below apply to Client Data submitted under Advanced Integration, whether by manually uploading files within the Platform or by establishing a secure, automated data feed through the Aparagon API, and to Client Data Aparagon captures, processes, and hashes through ACE; both methods are treated identically for purposes of this policy.
Protections
Aparagon never connects to an Advertiser’s internal data collection systems. Instead, each Advertiser using Advanced Integration submits its Client Data to the Aparagon Insights Engine, either by uploading files directly within the Platform or by pushing data through the Aparagon API, and, where an Advertiser enables ACE, Aparagon’s own script and infrastructure capture Client Data directly, as described below.
Data Transmission in Advanced Integrations. Whether Advertiser uploads files directly within the Platform or establishes an automated feed through the Aparagon API, Client Data is transmitted to Aparagon over a TLS connection. This significantly reduces the likelihood that the communication is intercepted or modified en route.
Client Data Storage. Client Data files are stored in a client-specific S3 bucket with Server Side Encryption. This provides protections from internal access as well as isolation from any other client’s data. As soon as Client Data is received by Aparagon, whether by upload or automated feed, it is encrypted with a client-unique key and stored in a short-term archive for troubleshooting or recovery from upload, feed, or configuration errors.
Client Data Processing. Client Data submitted under Advanced Integration is then converted into a form compatible for use within the cloud-based clean room environment called Amazon Marketing Cloud (AMC). AMC is a secure, privacy-first construct hosted on Amazon Web Services (AWS) that enables collaboration between independent data sources and Amazon Ads without directly sharing or exposing the underlying sensitive data of those parties.
To share data within AMC, all proprietary data must be hashed in accordance with strict procedures. This entails normalizing the data fields in a consistent form and hashing Personally Identifiable Information (PII) with an AES256 algorithm. Hashed data refers to information that has been processed and transformed into a seemingly random string of characters, known as a hash. This process is one-way, meaning the original data cannot be retrieved from the hash. The non-PII fields are categorized and mapped during the New Client Audience Creation Process. This mapping is provided by the individual client and may be amended from time to time, as needed.
Client Data within AMC is secure because no party can access or extract the underlying, proprietary information. The objective of AMC is to allow parties to perform analytics across pseudonymized signals. The queries run within AMC generate statistical outputs (i.e. counts) regarding the number of matches that can be produced between data sources. AMC has a requirement that at least 2,000 lines exist for any given upload and that 100 matches must exist for a query to produce an output. This process is intended to protect Client Data and make it significantly less likely that the data can be linked back to specific individuals while maintaining the data’s utility for advertising purposes.
Aparagon Conversion Events (ACE) Data. Where Advertiser enables ACE for an Account, Aparagon provides Advertiser a script and supporting backend infrastructure that captures conversion events occurring off of Amazon’s own properties, such as form submissions, account signups, and page views. Unlike Simple Integration, where the Amazon Ad tag captures event data directly into systems Amazon controls, ACE event data is captured and processed by Aparagon’s own infrastructure, following the same ingestion, encryption, and hashing pipeline described above for Client Data submitted under Advanced Integration, before being transmitted to Amazon Ads.
Consistent with the Aparagon Terms of Service, Aparagon will not use ACE to collect, name, describe, or transmit any sensitive personal information, including information related to an individual’s financial status or health or medical condition, and may reject, disable, or suspend any event name, conversion-type mapping, or associated value it reasonably believes would violate this restriction. Once transmitted to Amazon Ads, ACE event data resides within Amazon’s own systems; Aparagon cannot export, recover, or correct that data after transmission, consistent with Aparagon’s inability to return Client Data once received, described in Client Data Use below.
Simple Integration Event Data. Where Advertiser uses Simple Integration, the Amazon Ad tag captures event data directly into systems controlled by Amazon, including Amazon Marketing Cloud (AMC). Aparagon does not receive, store, or process the underlying event data. Instead, Aparagon queries AMC for aggregated, privacy-safe outputs, such as counts of matches between data sources, subject to AMC’s own privacy safeguards, including the minimum-threshold requirements described above (at least 2,000 lines per upload and 100 matches per query before a query may produce an output). Amazon’s terms and policies govern the collection and processing of event data captured by the Amazon Ad tag.
Client Data Use. Client Data is necessary to measure attribution and calculate the marketing insights that are used to improve campaign performance. This feedback allows for improved effectiveness of ad spend. In no case is Client Data from one client shared with any other client.
Persistence. The encrypted files of received Client Data, whether submitted under Advanced Integration or captured through ACE, are stored for 30 days, as listed in the Aparagon Data Retention Policy. Intermediate files used in processing are immediately removed after consumption by the subsequent processing step.
The Client Data Warehouse, which is client specific, is persisted and backed up on a daily basis. The encrypted backups are structured to allow for a rollback in time to a period up to 30 days prior.
APARAGON DATA RETENTION POLICY
Version 1.2
Introduction
It is imperative that appropriate security practices are defined and procedures are followed as Aparagon handles Advertiser-Provided Customer Data (“Client Data”) and Platform Data, as described in the Terms of Service (the “Terms”).
Purpose
The purpose of this policy is to describe the practices to be followed for the retention and disposal of data held and used by Aparagon.
Scope
This policy applies to all employees, subcontractors, and consultants of Aparagon who handle, manage, or use Client Data and Platform Data necessary to provide the Services. For purposes of this Policy, capitalized terms have the meanings assigned to them in the Terms.
Data Retention
Aparagon will accept and retain only the data necessary for providing the Services. The retention schedule below is based on the type of data as well as applicable operational requirements and the Terms. Each type of data will be maintained for the retention period indicated.
The “Client Data” rows below apply to Client Data that Advertiser submits to Aparagon under Advanced Integration, whether by manually uploading files within the Platform or by establishing a secure, automated data feed (as described in Terms), and to Client Data that Aparagon captures, processes, and hashes through Aparagon Conversion Events (“ACE”), each as described in the Aparagon Client Data Protection Policy above.
Aparagon does not receive, store, or otherwise retain the underlying event data captured by the Amazon Ad tag under Simple Integration; that data is captured and processed entirely within systems controlled by Amazon. Any aggregated outputs Aparagon receives from querying Amazon Marketing Cloud are treated as Platform Data, subject to the retention periods described below.
Data Retention Schedule.
| Type of Data | Description | Retention Period |
|---|---|---|
| Client Data | As-received by upload or Aparagon API | |
| Client Data (Encrypted) | Encrypted archive of file | 30 days |
| Client Data Warehouse | Client-specific processed data | 3 years |
| Platform Data | As generated on the Platform | |
| Client Reporting | Client-specific reporting | 13 months |
| Client Creative Asset | Client-specific creative asset | 13 months from date last used |
| Client Campaign Order | Client-specific campaign order | 13 months from order end date |
| Client Custom Audience | Client-specific custom audience | 13 months from date last used |
| Client Process Logs | Logs from client data processing, including ACE event processing | 90 days |
Data Disposal
The disposal — destruction or purge — of each type of data is to be completed by Aparagon as a standard practice following the listed retention period above; provided, however, that Aparagon also will suspend its retention and deletion policy with respect to any data that must be preserved under applicable Law or a legal or regulatory obligation, including a litigation hold, for so long as that requirement continues.
The retention periods listed above for Client Data (both the Encrypted archive and the Client Data Warehouse) apply only while the applicable Account or Profile remains active. Upon the termination or closure of the applicable Account or Profile, Aparagon will instead purge all Client Data within thirty (30) days, regardless of the retention periods otherwise listed above, as described in the “Confidentiality” section of the Terms.
This accelerated timeline does not apply to Platform Data, which continues to be retained per the schedule above notwithstanding the termination or closure of the applicable Account or Profile.
These policies work together with, and are subject to, the Aparagon Terms of Service, which controls in the event of any inconsistency.
